blob: 05f9303856523d55617cf9649a80d852fe59d29c [file] [log] [blame]
Ted Kremenekf6c62f32008-02-13 17:41:41 +00001//==- GRCoreEngine.cpp - Path-Sensitive Dataflow Engine ----------------*- C++ -*-//
Ted Kremenek3e743662008-01-14 23:24:37 +00002//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9//
10// This file defines a generic engine for intraprocedural, path-sensitive,
11// dataflow analysis via graph reachability engine.
12//
13//===----------------------------------------------------------------------===//
14
Ted Kremenekf6c62f32008-02-13 17:41:41 +000015#include "clang/Analysis/PathSensitive/GRCoreEngine.h"
Ted Kremenek3e743662008-01-14 23:24:37 +000016#include "clang/AST/Expr.h"
17#include "llvm/Support/Compiler.h"
18#include "llvm/Support/Casting.h"
19#include "llvm/ADT/DenseMap.h"
20#include <vector>
21
22using llvm::cast;
23using llvm::isa;
24using namespace clang;
25
26namespace {
27 class VISIBILITY_HIDDEN DFS : public GRWorkList {
28 llvm::SmallVector<GRWorkListUnit,20> Stack;
29public:
30 virtual bool hasWork() const {
31 return !Stack.empty();
32 }
33
34 virtual void Enqueue(const GRWorkListUnit& U) {
35 Stack.push_back(U);
36 }
37
38 virtual GRWorkListUnit Dequeue() {
39 assert (!Stack.empty());
40 const GRWorkListUnit& U = Stack.back();
41 Stack.pop_back(); // This technically "invalidates" U, but we are fine.
42 return U;
43 }
44};
45} // end anonymous namespace
46
Ted Kremenek2e12c2e2008-01-16 18:18:48 +000047// Place the dstor for GRWorkList here because it contains virtual member
48// functions, and we the code for the dstor generated in one compilation unit.
49GRWorkList::~GRWorkList() {}
50
Ted Kremenek3e743662008-01-14 23:24:37 +000051GRWorkList* GRWorkList::MakeDFS() { return new DFS(); }
52
53/// ExecuteWorkList - Run the worklist algorithm for a maximum number of steps.
Ted Kremenekf6c62f32008-02-13 17:41:41 +000054bool GRCoreEngineImpl::ExecuteWorkList(unsigned Steps) {
Ted Kremenek3e743662008-01-14 23:24:37 +000055
56 if (G->num_roots() == 0) { // Initialize the analysis by constructing
57 // the root if none exists.
58
Ted Kremenek997d8722008-01-29 00:33:40 +000059 CFGBlock* Entry = &getCFG().getEntry();
Ted Kremenek3e743662008-01-14 23:24:37 +000060
61 assert (Entry->empty() &&
62 "Entry block must be empty.");
63
64 assert (Entry->succ_size() == 1 &&
65 "Entry block must have 1 successor.");
66
67 // Get the solitary successor.
68 CFGBlock* Succ = *(Entry->succ_begin());
69
70 // Construct an edge representing the
71 // starting location in the function.
Ted Kremenek997d8722008-01-29 00:33:40 +000072 BlockEdge StartLoc(getCFG(), Entry, Succ);
Ted Kremenek3e743662008-01-14 23:24:37 +000073
Ted Kremenek90ae68f2008-02-12 18:08:17 +000074 // Set the current block counter to being empty.
75 WList->setBlockCounter(BCounterFactory.GetEmptyCounter());
76
Ted Kremenek3e743662008-01-14 23:24:37 +000077 // Generate the root.
78 GenerateNode(StartLoc, getInitialState());
79 }
80
81 while (Steps && WList->hasWork()) {
82 --Steps;
83 const GRWorkListUnit& WU = WList->Dequeue();
Ted Kremenek90ae68f2008-02-12 18:08:17 +000084
85 // Set the current block counter.
86 WList->setBlockCounter(WU.getBlockCounter());
87
88 // Retrieve the node.
Ted Kremenek3e743662008-01-14 23:24:37 +000089 ExplodedNodeImpl* Node = WU.getNode();
90
91 // Dispatch on the location type.
92 switch (Node->getLocation().getKind()) {
93 default:
94 assert (isa<BlockEdge>(Node->getLocation()));
95 HandleBlockEdge(cast<BlockEdge>(Node->getLocation()), Node);
96 break;
97
98 case ProgramPoint::BlockEntranceKind:
99 HandleBlockEntrance(cast<BlockEntrance>(Node->getLocation()), Node);
100 break;
101
102 case ProgramPoint::BlockExitKind:
Ted Kremeneke5843592008-01-15 00:24:08 +0000103 assert (false && "BlockExit location never occur in forward analysis.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000104 break;
Ted Kremenekfa5a3d02008-04-29 21:04:26 +0000105
106 case ProgramPoint::PostLoadKind:
Ted Kremenek3e743662008-01-14 23:24:37 +0000107 case ProgramPoint::PostStmtKind:
108 HandlePostStmt(cast<PostStmt>(Node->getLocation()), WU.getBlock(),
109 WU.getIndex(), Node);
110 break;
111 }
112 }
113
114 return WList->hasWork();
115}
116
Ted Kremenekdf4a5b92008-03-05 19:08:15 +0000117void GRCoreEngineImpl::HandleBlockEdge(const BlockEdge& L,
118 ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000119
120 CFGBlock* Blk = L.getDst();
121
122 // Check if we are entering the EXIT block.
Ted Kremenek997d8722008-01-29 00:33:40 +0000123 if (Blk == &getCFG().getExit()) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000124
Ted Kremenek997d8722008-01-29 00:33:40 +0000125 assert (getCFG().getExit().size() == 0
126 && "EXIT block cannot contain Stmts.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000127
Ted Kremenek811c2b42008-04-11 22:03:04 +0000128 // Process the final state transition.
129 GREndPathNodeBuilderImpl Builder(Blk, Pred, this);
130 ProcessEndPath(Builder);
Ted Kremenek3e743662008-01-14 23:24:37 +0000131
Ted Kremenek3e743662008-01-14 23:24:37 +0000132 // This path is done. Don't enqueue any more nodes.
133 return;
134 }
Ted Kremenek17f4dbd2008-02-29 20:27:50 +0000135
136 // FIXME: Should we allow ProcessBlockEntrance to also manipulate state?
Ted Kremenek3e743662008-01-14 23:24:37 +0000137
Ted Kremenek17f4dbd2008-02-29 20:27:50 +0000138 if (ProcessBlockEntrance(Blk, Pred->State, WList->getBlockCounter()))
139 GenerateNode(BlockEntrance(Blk), Pred->State, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000140}
141
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000142void GRCoreEngineImpl::HandleBlockEntrance(const BlockEntrance& L,
Ted Kremenekdf4a5b92008-03-05 19:08:15 +0000143 ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000144
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000145 // Increment the block counter.
146 GRBlockCounter Counter = WList->getBlockCounter();
147 Counter = BCounterFactory.IncrementCount(Counter, L.getBlock()->getBlockID());
148 WList->setBlockCounter(Counter);
149
150 // Process the entrance of the block.
Ted Kremenek3e743662008-01-14 23:24:37 +0000151 if (Stmt* S = L.getFirstStmt()) {
Ted Kremenekb2cad312008-01-29 22:11:49 +0000152 GRStmtNodeBuilderImpl Builder(L.getBlock(), 0, Pred, this);
Ted Kremenek3e743662008-01-14 23:24:37 +0000153 ProcessStmt(S, Builder);
154 }
Ted Kremeneke5843592008-01-15 00:24:08 +0000155 else
156 HandleBlockExit(L.getBlock(), Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000157}
158
159
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000160void GRCoreEngineImpl::HandleBlockExit(CFGBlock * B, ExplodedNodeImpl* Pred) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000161
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000162 if (Stmt* Term = B->getTerminator()) {
163 switch (Term->getStmtClass()) {
164 default:
165 assert(false && "Analysis for this terminator not implemented.");
166 break;
Ted Kremenek822f7372008-02-12 21:51:20 +0000167
168 case Stmt::BinaryOperatorClass: // '&&' and '||'
169 HandleBranch(cast<BinaryOperator>(Term)->getLHS(), Term, B, Pred);
170 return;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000171
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000172 case Stmt::ConditionalOperatorClass:
173 HandleBranch(cast<ConditionalOperator>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000174 return;
175
176 // FIXME: Use constant-folding in CFG construction to simplify this
177 // case.
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000178
179 case Stmt::ChooseExprClass:
180 HandleBranch(cast<ChooseExpr>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000181 return;
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000182
Ted Kremenek822f7372008-02-12 21:51:20 +0000183 case Stmt::DoStmtClass:
184 HandleBranch(cast<DoStmt>(Term)->getCond(), Term, B, Pred);
185 return;
186
187 case Stmt::ForStmtClass:
188 HandleBranch(cast<ForStmt>(Term)->getCond(), Term, B, Pred);
189 return;
Ted Kremenek632bcb82008-02-13 16:56:51 +0000190
191 case Stmt::ContinueStmtClass:
192 case Stmt::BreakStmtClass:
193 case Stmt::GotoStmtClass:
Ted Kremenek3f2f1ad2008-02-05 00:26:40 +0000194 break;
195
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000196 case Stmt::IfStmtClass:
197 HandleBranch(cast<IfStmt>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000198 return;
Ted Kremenek7022efb2008-02-13 00:24:44 +0000199
200 case Stmt::IndirectGotoStmtClass: {
201 // Only 1 successor: the indirect goto dispatch block.
202 assert (B->succ_size() == 1);
203
204 GRIndirectGotoNodeBuilderImpl
205 builder(Pred, B, cast<IndirectGotoStmt>(Term)->getTarget(),
206 *(B->succ_begin()), this);
207
208 ProcessIndirectGoto(builder);
209 return;
210 }
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000211
Ted Kremenek80ebc1d2008-02-13 23:08:21 +0000212 case Stmt::SwitchStmtClass: {
213 GRSwitchNodeBuilderImpl builder(Pred, B,
214 cast<SwitchStmt>(Term)->getCond(),
215 this);
216
217 ProcessSwitch(builder);
218 return;
219 }
220
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000221 case Stmt::WhileStmtClass:
222 HandleBranch(cast<WhileStmt>(Term)->getCond(), Term, B, Pred);
Ted Kremenek822f7372008-02-12 21:51:20 +0000223 return;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000224 }
225 }
Ted Kremenek822f7372008-02-12 21:51:20 +0000226
227 assert (B->succ_size() == 1 &&
228 "Blocks with no terminator should have at most 1 successor.");
Ted Kremenek3e743662008-01-14 23:24:37 +0000229
Ted Kremenek822f7372008-02-12 21:51:20 +0000230 GenerateNode(BlockEdge(getCFG(),B,*(B->succ_begin())), Pred->State, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000231}
232
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000233void GRCoreEngineImpl::HandleBranch(Expr* Cond, Stmt* Term, CFGBlock * B,
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000234 ExplodedNodeImpl* Pred) {
235 assert (B->succ_size() == 2);
236
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000237 GRBranchNodeBuilderImpl Builder(B, *(B->succ_begin()), *(B->succ_begin()+1),
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000238 Pred, this);
239
240 ProcessBranch(Cond, Term, Builder);
241}
242
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000243void GRCoreEngineImpl::HandlePostStmt(const PostStmt& L, CFGBlock* B,
Ted Kremenek3e743662008-01-14 23:24:37 +0000244 unsigned StmtIdx, ExplodedNodeImpl* Pred) {
245
246 assert (!B->empty());
247
Ted Kremeneke5843592008-01-15 00:24:08 +0000248 if (StmtIdx == B->size())
249 HandleBlockExit(B, Pred);
Ted Kremenek3e743662008-01-14 23:24:37 +0000250 else {
Ted Kremenekb2cad312008-01-29 22:11:49 +0000251 GRStmtNodeBuilderImpl Builder(B, StmtIdx, Pred, this);
Ted Kremeneke914bb82008-01-16 22:13:19 +0000252 ProcessStmt((*B)[StmtIdx], Builder);
Ted Kremenek3e743662008-01-14 23:24:37 +0000253 }
254}
255
256typedef llvm::DenseMap<Stmt*,Stmt*> ParentMapTy;
257/// PopulateParentMap - Recurse the AST starting at 'Parent' and add the
258/// mappings between child and parent to ParentMap.
259static void PopulateParentMap(Stmt* Parent, ParentMapTy& M) {
260 for (Stmt::child_iterator I=Parent->child_begin(),
261 E=Parent->child_end(); I!=E; ++I) {
262
263 assert (M.find(*I) == M.end());
264 M[*I] = Parent;
265 PopulateParentMap(*I, M);
266 }
267}
268
269/// GenerateNode - Utility method to generate nodes, hook up successors,
270/// and add nodes to the worklist.
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000271void GRCoreEngineImpl::GenerateNode(const ProgramPoint& Loc, void* State,
Ted Kremenek3e743662008-01-14 23:24:37 +0000272 ExplodedNodeImpl* Pred) {
273
274 bool IsNew;
275 ExplodedNodeImpl* Node = G->getNodeImpl(Loc, State, &IsNew);
276
277 if (Pred)
278 Node->addPredecessor(Pred); // Link 'Node' with its predecessor.
279 else {
280 assert (IsNew);
281 G->addRoot(Node); // 'Node' has no predecessor. Make it a root.
282 }
283
284 // Only add 'Node' to the worklist if it was freshly generated.
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000285 if (IsNew) WList->Enqueue(Node);
Ted Kremenek3e743662008-01-14 23:24:37 +0000286}
287
Ted Kremenekb2cad312008-01-29 22:11:49 +0000288GRStmtNodeBuilderImpl::GRStmtNodeBuilderImpl(CFGBlock* b, unsigned idx,
Ted Kremenekf6c62f32008-02-13 17:41:41 +0000289 ExplodedNodeImpl* N, GRCoreEngineImpl* e)
Ted Kremenekc072b822008-04-18 20:35:30 +0000290 : Eng(*e), B(*b), Idx(idx), Pred(N), LastNode(N) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000291 Deferred.insert(N);
292}
293
Ted Kremenekb2cad312008-01-29 22:11:49 +0000294GRStmtNodeBuilderImpl::~GRStmtNodeBuilderImpl() {
Ted Kremenek3e743662008-01-14 23:24:37 +0000295 for (DeferredTy::iterator I=Deferred.begin(), E=Deferred.end(); I!=E; ++I)
Ted Kremeneka50d9852008-01-30 23:03:39 +0000296 if (!(*I)->isSink())
Ted Kremenek3e743662008-01-14 23:24:37 +0000297 GenerateAutoTransition(*I);
298}
299
Ted Kremenekb2cad312008-01-29 22:11:49 +0000300void GRStmtNodeBuilderImpl::GenerateAutoTransition(ExplodedNodeImpl* N) {
Ted Kremeneka50d9852008-01-30 23:03:39 +0000301 assert (!N->isSink());
Ted Kremenek3e743662008-01-14 23:24:37 +0000302
303 PostStmt Loc(getStmt());
304
305 if (Loc == N->getLocation()) {
306 // Note: 'N' should be a fresh node because otherwise it shouldn't be
307 // a member of Deferred.
308 Eng.WList->Enqueue(N, B, Idx+1);
309 return;
310 }
311
312 bool IsNew;
313 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(Loc, N->State, &IsNew);
314 Succ->addPredecessor(N);
315
316 if (IsNew)
317 Eng.WList->Enqueue(Succ, B, Idx+1);
318}
319
Ted Kremenekfa5a3d02008-04-29 21:04:26 +0000320ExplodedNodeImpl*
321GRStmtNodeBuilderImpl::generateNodeImpl(Stmt* S, void* State,
322 ExplodedNodeImpl* Pred, bool isLoad) {
Ted Kremenek3e743662008-01-14 23:24:37 +0000323
324 bool IsNew;
Ted Kremenekfa5a3d02008-04-29 21:04:26 +0000325 ProgramPoint Loc = isLoad ? PostLoad(S) : PostStmt(S);
326 ExplodedNodeImpl* N = Eng.G->getNodeImpl(Loc, State, &IsNew);
Ted Kremenek3e743662008-01-14 23:24:37 +0000327 N->addPredecessor(Pred);
328 Deferred.erase(Pred);
329
Ted Kremenek3e743662008-01-14 23:24:37 +0000330 if (IsNew) {
331 Deferred.insert(N);
332 LastNode = N;
333 return N;
334 }
335
336 LastNode = NULL;
337 return NULL;
338}
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000339
Ted Kremeneka50d9852008-01-30 23:03:39 +0000340ExplodedNodeImpl* GRBranchNodeBuilderImpl::generateNodeImpl(void* State,
341 bool branch) {
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000342 bool IsNew;
343
344 ExplodedNodeImpl* Succ =
345 Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src, branch ? DstT : DstF),
346 State, &IsNew);
347
348 Succ->addPredecessor(Pred);
349
Ted Kremenek7ff18932008-01-29 23:32:35 +0000350 if (branch) GeneratedTrue = true;
351 else GeneratedFalse = true;
352
Ted Kremeneka50d9852008-01-30 23:03:39 +0000353 if (IsNew) {
Ted Kremenek2531fce2008-01-30 23:24:39 +0000354 Deferred.push_back(Succ);
Ted Kremeneka50d9852008-01-30 23:03:39 +0000355 return Succ;
356 }
357
358 return NULL;
Ted Kremenek9b4211d2008-01-29 22:56:11 +0000359}
Ted Kremenek7ff18932008-01-29 23:32:35 +0000360
361GRBranchNodeBuilderImpl::~GRBranchNodeBuilderImpl() {
362 if (!GeneratedTrue) generateNodeImpl(Pred->State, true);
363 if (!GeneratedFalse) generateNodeImpl(Pred->State, false);
Ted Kremenek2531fce2008-01-30 23:24:39 +0000364
365 for (DeferredTy::iterator I=Deferred.begin(), E=Deferred.end(); I!=E; ++I)
Ted Kremenek90ae68f2008-02-12 18:08:17 +0000366 if (!(*I)->isSink()) Eng.WList->Enqueue(*I);
Ted Kremenek7ff18932008-01-29 23:32:35 +0000367}
Ted Kremenek7022efb2008-02-13 00:24:44 +0000368
Ted Kremenek7022efb2008-02-13 00:24:44 +0000369
370ExplodedNodeImpl*
Ted Kremenek2bba9012008-02-13 17:27:37 +0000371GRIndirectGotoNodeBuilderImpl::generateNodeImpl(const Iterator& I,
Ted Kremenek7022efb2008-02-13 00:24:44 +0000372 void* St,
373 bool isSink) {
374 bool IsNew;
375
376 ExplodedNodeImpl* Succ =
Ted Kremenek2bba9012008-02-13 17:27:37 +0000377 Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src, I.getBlock(), true),
Ted Kremenek7022efb2008-02-13 00:24:44 +0000378 St, &IsNew);
379
380 Succ->addPredecessor(Pred);
381
382 if (IsNew) {
383
384 if (isSink)
385 Succ->markAsSink();
386 else
387 Eng.WList->Enqueue(Succ);
388
389 return Succ;
390 }
391
392 return NULL;
393}
Ted Kremenek80ebc1d2008-02-13 23:08:21 +0000394
395
396ExplodedNodeImpl*
397GRSwitchNodeBuilderImpl::generateCaseStmtNodeImpl(const Iterator& I, void* St) {
398
399 bool IsNew;
400
401 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src,
402 I.getBlock()),
403 St, &IsNew);
404 Succ->addPredecessor(Pred);
405
406 if (IsNew) {
407 Eng.WList->Enqueue(Succ);
408 return Succ;
409 }
410
411 return NULL;
412}
413
414
415ExplodedNodeImpl*
416GRSwitchNodeBuilderImpl::generateDefaultCaseNodeImpl(void* St, bool isSink) {
417
418 // Get the block for the default case.
419 assert (Src->succ_rbegin() != Src->succ_rend());
420 CFGBlock* DefaultBlock = *Src->succ_rbegin();
421
422 bool IsNew;
423
424 ExplodedNodeImpl* Succ = Eng.G->getNodeImpl(BlockEdge(Eng.getCFG(), Src,
425 DefaultBlock),
426 St, &IsNew);
427 Succ->addPredecessor(Pred);
428
429 if (IsNew) {
430 if (isSink)
431 Succ->markAsSink();
432 else
433 Eng.WList->Enqueue(Succ);
434
435 return Succ;
436 }
437
438 return NULL;
439}
Ted Kremenek811c2b42008-04-11 22:03:04 +0000440
441GREndPathNodeBuilderImpl::~GREndPathNodeBuilderImpl() {
442 // Auto-generate an EOP node if one has not been generated.
443 if (!HasGeneratedNode) generateNodeImpl(Pred->State);
444}
445
446ExplodedNodeImpl* GREndPathNodeBuilderImpl::generateNodeImpl(void* State) {
447 HasGeneratedNode = true;
448
449 bool IsNew;
450
451 ExplodedNodeImpl* Node =
Ted Kremenek86051692008-04-16 22:30:40 +0000452 Eng.G->getNodeImpl(BlockEntrance(&B), State, &IsNew);
Ted Kremenek811c2b42008-04-11 22:03:04 +0000453
454
455 Node->addPredecessor(Pred);
456
457 if (IsNew) {
458 Node->markAsSink();
459 Eng.G->addEndOfPath(Node);
Ted Kremenekd004c412008-04-18 16:30:14 +0000460 return Node;
Ted Kremenek811c2b42008-04-11 22:03:04 +0000461 }
462
Ted Kremenekd004c412008-04-18 16:30:14 +0000463 return NULL;
Ted Kremenek811c2b42008-04-11 22:03:04 +0000464}